CISA - Protection of Information Assets (26% of the exam) - Section 5.1

Assess identity and access management controls protecting information assets.

Describe identity and access management principles including authentication methods, authorisation models and the role of access controls in limiting user rights to the minimum required. Assess whether implemented controls enforce least privilege, segregation of duties and timely de-provisioning of accounts.

identity and access managementauthenticationauthorizationaccess controls

Practice question for this objective

Free sampleProtection of Information Assetsmedium

Which control type BEST describes a quarterly user access review that compares active accounts in a financial application against current human resources records?

  • APreventive control, because the review stops unauthorised users from obtaining access to the financial application in the first place.
  • BCorrective control, because the review automatically rolls back any incorrect permissions found in the financial application during the review.
  • CCompensating control, because the review substitutes for the absence of a primary segregation of duties control inside the financial application.
  • DDetective control, because the review identifies access that no longer aligns with current employment after it has been granted. Correct
Classify periodic user access reviews as detective controls within the identity and access management lifecycle. Detective controls operate after a transaction or state change to surface deviations from policy; a periodic reconciliation of provisioned accounts against authoritative employment records identifies orphaned or excess access after the fact, which fits the detective control definition rather than preventive, corrective or compensating categories.

Why A is wrong: A preventive control would block inappropriate access before it occurs, but a periodic review takes place after provisioning, so this classification reflects a common confusion about control timing.

Why B is wrong: Corrective controls remediate after detection, and the review itself does not perform the rollback; it produces findings that then drive corrective action, so this confuses detection with the follow-up remediation step.

Why C is wrong: A compensating control substitutes for a missing primary control by management decision, whereas a routine access review is a standalone monitoring activity rather than a substitute, making this a plausible but incorrect classification.

Why D is correct: User access reviews are after-the-fact comparisons that surface dormant, terminated or transferred user accounts that already exist, which is the defining characteristic of a detective control.

See more CISA practice questions, answers explained.

Exam traps in Protection of Information Assets

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • Authentication enforces least privilege at the data layer, while authorisation merely records a successful credential validation in the audit log.

    Why it is wrong: This conflates terms: least privilege is an authorisation principle, not an authentication function, and credential validation is the act of authentication itself rather than a logging side effect.

  • Least privilege requires that every user receive identical baseline access to streamline provisioning and reduce administrative overhead across the organisation.

    Why it is wrong: Uniform baseline access contradicts least privilege because it grants rights that some users do not need, and it confuses administrative simplicity with a security control objective.

  • Accept the position because management has documented the rationale and the situation is temporary during the migration.

    Why it is wrong: Documented rationale alone does not retire the segregation of duties risk; without compensating monitoring, the conflict remains exploitable, so simple acceptance fails to satisfy audit responsibilities.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.